After Bitget’s $351.6 million hack, the real question is who can still stop the money

After Bitget’s $351.6 million hack, the real question is who can still stop the money

N
News Editor
2026-09-28 10:13:00
Bitget said it detected abnormal transfers from some hot and warm wallets at 02:31:11 Beijing time on Sept. 25, 2026, with an initial estimated loss of about $351.6 million. The exchange said its cold wallets were not affected, the loss falls within its user protection fund, and withdrawals were temporarily suspended pending security checks. PANews’ original article uses the incident to examine a harder issue than the headline number: once stolen crypto starts moving, which parties along the route still have the authority to act, what evidence they need, and how temporary restrictions can be turned into formal recovery procedures. The piece walks through exchanges, swap services, cross-chain protocols and aggregators, arguing that labels such as “decentralized” matter less than actual control over accounts, routing, execution, upgrades or front ends. It also cites past examples involving Bybit, Elliptic, Binance, Huobi, OKX, ChangeNOW, the UK Piroozzadeh ruling and Germany’s investigation into eXch to show how tracing, account matching, legal process, disclosure limits and anti-money-laundering duties can intersect after a major theft.

Author: Shao Jiadian

After Bitget’s $351.6 million hack, the real question is who can still stop the money 2

Another exchange hack has hit the crypto market. This time, the victim is Bitget, and the amount involved is about $350 million.

In a security notice released after the incident, Bitget said that at 02:31:11 Beijing time on Sept. 25, 2026, its system detected abnormal transfers from some hot and warm wallets. The exchange put the preliminary amount at about $351.6 million and said its cold wallets were not affected. Bitget also said the loss falls within the coverage of its user protection fund and that withdrawals were temporarily suspended until security checks are completed.

PANews’ article does not stop at the size of the loss. It shifts the focus to a more practical question: once the funds move, who can still do anything about them? Covering the loss is Bitget’s immediate problem. Stopping the money, if that is still possible, depends on the exchanges, swap services, cross-chain protocols, aggregators and the people who actually control the relevant parts of those businesses.

After the incident, Bybit co-founder and CEO Ben Zhou said he was willing to help Bitget and that his team was updating the LazarusBounty platform to assist with tracking the stolen funds. The article treats that as a positive example of industry support in a crisis.

It points to an earlier case as well. After Bybit was hacked in 2025, Bitget CEO Gracy Chen publicly said Bitget would help with tracing and investigation. According to Bybit’s official incident timeline, Bitget also transferred 40,000 ETH to Bybit at the time to provide liquidity support. Liquidity support and asset recovery are not the same thing, the article notes, but both show that a single platform is rarely able to handle every part of a major security response on its own.

Step one: identify who actually has the power to act

The hard work starts after the public statements. Stolen assets can be swapped into other tokens, split across multiple addresses or bridged to another chain in a short period of time. Some services along that route control custodial accounts. Some control transactions that have not yet settled. Others may only control a front end, routing, forwarding or part of the execution flow. For investigators and the victim, the first task is to identify which party can actually take action.

The article frames recovery cooperation around three questions: whether on-chain addresses can be matched to specific transactions, whether business authority can be turned into concrete action, and whether temporary restrictions can be connected to formal procedures. Public support may show goodwill. Whether funds can be stopped depends on who controls each step, how far the transaction has progressed, what the available materials support, and how disclosure, preservation and return can later be handled.

Turning support into action starts with identifying who holds real authority in the relevant transaction. A service that receives assets, performs a swap and only then pays out may still control assets that have not settled. A custodial exchange may control linked accounts and deposit or withdrawal permissions. Operators of cross-chain protocols or aggregators may control only the front end, routing, transaction forwarding or part of execution.

PANews argues that platform names and technical labels are only a starting point. What matters is the business process and the control relationship. That helps the victim identify the right recipient for a request. It also helps the recipient determine what it can pause, verify or preserve, and what lies outside its authority.

Legal duties also depend on the business model and the applicable jurisdiction. Under Financial Action Task Force, or FATF, standards, virtual asset service providers are generally expected to implement customer due diligence, recordkeeping and suspicious transaction reporting, but the exact scope and method depend on local law. If a legal duty to verify, preserve or report has already been triggered, it should be handled under the applicable rules. Whether a business can also restrict a transaction or disclose information to a specific party is a separate question.

The article says the same analysis applies to businesses using decentralized technology. In its DeFi report published in July 2026, FATF focused on who has control over, or sufficient influence on, a given arrangement, listing factors such as administrative rights, upgrade control, concentration of governance tokens and influence over infrastructure. For cross-chain protocols and aggregators, the article says, the services an operator actually provides and the parts it controls usually say more than the word “decentralized.”

Step two: match on-chain addresses to actual transactions

Once a potentially relevant party has been identified, the next step is to connect the on-chain path to that party’s accounts, orders and business records. Address labels only point investigators in a direction. A service provider is in a much better position to judge whether funds are still within its control, and what room it has to act, when the trace is tied to a specific transaction.

The article says a victim platform or its authorized agent can make a cooperation request more useful by clearly setting out the facts of the case, the blockchain involved, transaction hashes, token types, amounts, timestamps, relevant addresses and the connection between those clues and the recipient’s business. The receiving service can then verify the requester’s identity, the source of the materials and the link to its own transactions under its internal process.

How far a transaction has progressed is a key clue. For services that receive first and pay out after conversion, the control position differs depending on whether the assets have not yet been swapped, have been swapped but not yet paid out, or have already been paid out. For cross-chain or aggregation services, operators can compare source-chain transactions, swap requests, destination-chain addresses and execution status using the information they lawfully hold. What exactly needs to be checked depends on the business architecture, the records the operator lawfully possesses and the applicable requirements.

Once outside intelligence is matched to a real account, a custodial exchange may be able to act if it has the authority and basis to do so. The article cites Elliptic’s disclosure that in 2023 Binance and Huobi froze accounts holding about $1.4 million in crypto based on intelligence it provided, with the funds linked to the earlier Harmony Horizon bridge attack. The point of that example is not that every platform can do the same. It is that the external trace was matched to accounts under exchange control.

Step three: choose measures based on the transaction stage

Once a clue is tied to a specific transaction, the question changes from what was found to what can still be done. Restricting access points, pausing swaps, delaying payout and restricting withdrawals from custodial accounts are different measures with different targets, legal bases and effects. Operators have to weigh the urgency of ongoing fund movement, the reliability of the materials in hand and the rights of ordinary users.

If assets are still unsettled and remain under a service provider’s control, the provider can assess whether it is feasible to stop a swap or delay payout based on applicable law, contractual arrangements, technical capability and the impact on the user involved. The article stresses that an unfinished transaction does not automatically create a duty to freeze or return assets, but it may create time for temporary review. A custodial exchange dealing with a linked account also needs to examine the basis, scope and duration for restricting outbound transfers.

Operators of cross-chain protocols and aggregators first need to map out which parts they control. If they only manage a front end, any measure may be limited to that access point. If they also control forwarding or execution, there may be more room to intervene. If contract pauses or upgrades are involved, multisig arrangements, governance procedures and the impact on other users also affect whether a measure is workable.

The article adds that restricting an entry point can reduce the risk of a service being used again, but the real effect depends on the architecture and on whether other access paths remain open. If users can still reach the service through another front end or by calling the contract directly, blocking a single front end may have limited value.

As an example, the article cites OKX’s March 17, 2025 announcement. OKX said that after discovering that Lazarus had tried to abuse its DeFi service, it proactively suspended its DEX aggregator service and upgraded protective measures after communicating with regulators. The announcement also said the aggregator connected liquidity from multiple protocols and did not itself custody customer assets. The article uses that case to show that a non-custodial service can still adjust the product and access points it controls, while the ability to freeze funds in the underlying protocol depends on the actual architecture and control rights.

After Bitget’s $351.6 million hack, the real question is who can still stop the money 3

When operators adopt temporary measures, they can also consider scope, review points, conditions for lifting the measure and record retention. If a binding law enforcement or court order applies to them, they should act within its force and scope. If there are doubts about the scope of execution or technical feasibility, they can explain that through the relevant process and seek clarification. Even if the funds have already moved on, lawfully retained account, order, login and communication records may still help later recovery efforts.

Step four: connect temporary restrictions to formal return procedures

Stopping funds for a moment only creates a window. Whether assets can actually be returned depends on who owns them, what can be delivered, to whom they should be delivered and under what procedure. After swaps and multiple transfers, counterparties may claim their own lawful basis for the transaction and for acquiring the assets. If funds have entered an exchange pool, the claimant may also need to prove the link between the controlled assets and the original stolen funds.

Temporary transfer restrictions and final return usually involve different conditions and evidentiary burdens. A party that only manages a front end and does not control the assets may be able to help mainly by providing records it lawfully holds. A party that holds customer or order information must also consider the recipient, the scope of disclosure, confidentiality duties and personal data protection rules before sharing anything externally.

Judicial measures also require the claimant to prepare the evidence and procedure properly. The article cites the 2023 ruling in the UK Piroozzadeh case, where the victim obtained an interim proprietary injunction without notifying Binance, only for the court to later discharge it because the applicant had not presented the case fully and fairly. The ruling discussed issues including a possible bona fide purchaser defense by the exchange and how preservation might work once funds had been mixed into a pool. The article notes that the case dealt with an interim injunction application rather than a final ruling on ownership, but it still shows that on-chain tracing alone is not enough to secure judicial relief.

Public rules from swap services reflect the same distinction. ChangeNOW’s public cooperation guidance asks requesters to provide case details, transaction information, address lists and law enforcement process information. Its terms of service, in Clause 6.11, also say that depending on when a report is received, the platform may only intercept a transaction after the swap has already been completed, in which case the returnable asset may be the post-conversion token. Under that clause, a clear request from law enforcement is also needed for return. The article notes that this is ChangeNOW’s publicly disclosed mechanism; other services may handle such cases differently depending on applicable law, contractual arrangements, asset status and procedure.

What different participants should do first

The article then turns to practice. The biggest problem, it says, is often not a lack of willingness to help, but uncertainty over who should send the next email, what should be attached and who should make the decision after receipt. Fund flows do not wait for everyone to get familiar with the process.

For the victim platform or project team, the article suggests fixing the incident timeline first, organizing transaction hashes, involved addresses, token types, amounts and on-chain paths, and preparing ownership, police report and authorization materials. External cooperation requests are best sent through a single contact point, with a clear explanation of what the recipient is being asked to verify, how far the current clues go and how the formal process is being advanced.

For exchanges, swap services and similar operators, the article says they can first check linked accounts, orders and transaction stages after receiving a lead, preserve KYC, login, device, communication and operation records, and then have business, technical, compliance and legal staff assess what measures are available within their authority. If something has not yet been confirmed, they can say it is still under review. If measures have already been taken, and if the law allows communication, they can also tell the requester what was done and what the limits are.

For cross-chain protocols, aggregators and related operators, the article recommends quickly separating out the smart contracts, front end, routing, APIs, upgrade rights and governance mechanisms to determine which parts are actually under their control. If they plan to adjust access points, suspend services or trigger a multisig or governance process, they should also assess alternative access paths, the impact on ordinary users and the conditions for restoration, while keeping records of the facts and authority relied on in making the decision.

For lawyers and on-chain investigation teams, the focus is to turn the on-chain path into a factual record that internal platform teams, law enforcement agencies and courts can all understand, and to match each request to a specific party, authority and procedure. Where multiple jurisdictions or service providers are involved, the sequence of materials and actions also needs to be designed so that clues do not remain stuck at the level of an address list and temporary restrictions do not become disconnected from later preservation, disclosure and return.

The article adds that the earlier all parties work from the same factual record, the easier it becomes to connect verification, restriction, disclosure and return. It also says operators can prepare in advance by setting up risk-intelligence intake channels and internal decision processes, clarifying who receives requests, who determines transaction links, who evaluates legal grounds and when escalation to management or outside specialists is needed.

Liability still turns on the evidence

On liability, the article says the issue can only be discussed accurately once the cooperation process is clearer. A delayed response, a mistaken risk judgment, a continuing failure to meet anti-money-laundering duties and knowingly helping criminal funds move are not the same thing in fact or in law. For protocols or applications, liability also has to be tied to a specific operator or controller. Being a developer or governance participant, by itself, does not directly settle the question.

From a regulatory perspective, the first step is to determine whether the relevant party is an obligated entity under the applicable law, and then to assess the specific due diligence, recordkeeping and reporting duties. FATF’s suspicious transaction reporting standard requires countries to impose legal rules under which financial institutions must promptly report to financial intelligence units when they suspect, or have reasonable grounds to suspect, that funds are criminal proceeds. For virtual asset service providers subject to local law, the reporting entity, trigger and method still depend on local rules.

The article draws a clear line between filing a suspicious transaction report with a competent authority and disclosing customer information to the victim. Those are different acts with different legal bases and boundaries, and reporting information may itself be subject to confidentiality restrictions. Whether an operator can say publicly that it has filed a report or is conducting an investigation depends on the applicable rules. More serious allegations, such as assisting money laundering, require proof of the conduct, the relevant state of mind and any other elements required by local law.

The article also cites Germany’s 2025 investigation into the crypto swap service eXch. Elliptic had traced some of the ETH stolen from Bybit as being converted into BTC through eXch and other services. Germany’s Federal Criminal Police Office later said that on April 30, 2025, law enforcement seized eXch servers in Germany and crypto assets worth about 34 million euros at the time. The operators were suspected of commercial money laundering and operating an internet-based criminal trading platform. The notice also said the service had advertised on underground networks that it did not implement anti-money-laundering measures and did not require users to verify their identities. The article adds that any criminal allegation still has to be proven under the relevant legal elements and evidence.

The lesson from that case is direct. Investigators do not only look at where the money passed. They also look at how a service solicited business, how it organized swaps and what it did when risk signals appeared. Keeping the necessary verification and decision records can help an operator show when it identified a risk, what authority it had at the time and why it did or did not take a particular step. The scope and retention period for those records still need to comply with applicable rules, and their evidentiary value has to be assessed together with other evidence.

The article’s closing point

The piece ends with a simple conclusion: recovery often depends on whether all parties can connect authority, evidence and procedure in the shortest possible time. Public support shows goodwill, but stopping assets, getting records into an investigation and creating a basis for return all require specific work.

In the author’s view, the hardest part is usually building an executable recovery chain out of on-chain paths, account and order information, business control rights, legal grounds and cross-border procedure. The earlier on-chain investigators, platform compliance teams, technical staff and lawyers work from the same factual record, the easier it becomes to connect verification, restriction, disclosure, preservation and return. For institutions that have already seen abnormal asset movement, or may receive cooperation requests in the future, mapping authority, preserving evidence and designing response paths early can reduce the risk of missing the window to act.

The article closes on trust. Users entrust platforms with assets, but also with confidence. A mature industry is not defined by how many supportive statements appear after an incident. It is defined by whether those statements can be turned into action that has a legal basis, can be executed and leaves a record. The final line puts it plainly: hopefully the industry sees fewer stories that begin with “again,” and more that end with “the funds were recovered,” backed by evidence.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.